CVE-2019-19340
published 2019-12-19CVE-2019-19340: A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e…
PriorityP349high8.2CVSS 3.1
AVNACLPRNUINSUCHINAL
EPSS
1.53%
72.0th percentile
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | tower | — | — |
| red_hat | tower | — | — |
| redhat | ansible_tower | >= 3.5.0 < 3.5.3 | 3.5.3 |
| redhat | ansible_tower | >= 3.6.0 < 3.6.2 | 3.6.2 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv3.08.2HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Tower: enabling RabbitMQ manager in the installer exposes the management interface publicly
vendor_redhat·2019-12-14·CVSS 8.2
CVE-2019-19340 [HIGH] CWE-1188 Tower: enabling RabbitMQ manager in the installer exposes the management interface publicly
Tower: enabling RabbitMQ manager in the installer exposes the management interface publicly
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
A flaw was found in Ansible Tower 3.6.1 and 3.5.3 where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
Mitigation: The issue could be mitigated by li
GHSA
GHSA-7844-v3mr-c966: A flaw was found in Ansible Tower, versions 3
ghsa_unreviewed·2022-05-24
CVE-2019-19340 [HIGH] CWE-1188 GHSA-7844-v3mr-c966: A flaw was found in Ansible Tower, versions 3
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.
No detection rules found.
No public exploits indexed.
2019-12-19
Published